Edwin Kwan
  • Home
  • Speaker
  • Podcasts
    • Cyber Bites
    • AppSec Unlocked
    • It’s 5:05 Podcast
  • Journal
  • Publications
Select Page

Nearly 800,000 Telnet Servers Exposed Globally as Critical Authentication Bypass Vulnerability Faces Active Exploitation

Jan 26, 2026 | Podcast

https://www.bleepingcomputer.com/news/security/nearly-800-000-telnet-servers-exposed-to-remote-attacks Internet security watchdog Shadowserver is tracking nearly 800,000 IP addresses with Telnet fingerprints amid ongoing attacks exploiting a critical authentication...

Predictable Password Patterns Persist as Billions Continue Using Easily Cracked Credentials

Jan 23, 2026 | Podcast

https://www.welivesecurity.com/en/cybersecurity/old-habits-die-hard-2025-most-common-passwords The password “123456” continues to reign as the most commonly used password globally across all age groups, with a full 25 percent of the top 1,000 most-used...

Attackers Weaponise Zendesk Support Systems in Massive Global Spam Campaign

Jan 22, 2026 | Podcast

Your Inbox Is Under Attack — Even Trusted Support Emails Are Being Abused A widespread spam campaign exploited unsecured Zendesk customer support systems to flood users worldwide with hundreds of automated emails from legitimate companies beginning around January 18....

AI-Powered Browsers Reverse Decades of Web Security Advances, Researchers Warn

Jan 21, 2026 | Podcast

https://www.darkreading.com/application-security/ai-agents-undermine-progress-browser-security Agentic browsers powered by artificial intelligence are undermining years of progress in web security by reintroducing vulnerabilities that modern browsers had largely...

GitLab Releases Emergency Patches for Two-Factor Authentication Bypass and Denial-of-Service Vulnerabilities

Jan 20, 2026 | Podcast

https://about.gitlab.com/releases/2026/01/21/patch-release-gitlab-18-8-2-released/#cve-2026-0723—unchecked-return-value-issue-in-authentication-services-impacts-gitlab-ceee GitLab has addressed a critical security issue that permitted attackers with knowledge of...

Fortune 500 Companies Compromised Through Vulnerable Security Testing Applications

Jan 19, 2026 | Podcast

When the Lab Door Stays Open: Exposed Training Apps Exploited for Fortune 500 Cloud Breaches Cybercriminals are targeting intentionally vulnerable web applications that organisations use for security training and penetration testing, gaining unauthorised access to...
« Older Entries
Next Entries »

Latest Posts

  • 60% of MD5 Password Hashes Now Crackable in Under an Hour With a Single GPU
  • Survey Finds 1 in 8 Employees Consider Selling Company Login Credentials Justifiable
  • Malicious OpenClaw Skill Weaponizes AI Agent Framework to Distribute Malwar
  • ACSC Issues Warning Over ClickFix Attacks Deploying Vidar Stealer Malware
  • Cybercriminals Abuse Amazon SES to Launch Undetected Phishing Campaigns

Speaking Events

  • Guest Lecture at UNSW Business School for INFS5907
  • Speaker at Bugcrowd Luncheon
  • Guest Lecture at UNSW
  • Panelist at SecTalks Legends – 2025
  • Keynote Speaker at Sydney AI Security Summit 2025

More Content

  • Articles (26)
  • Podcast (782)
  • Posts (26)
  • Publications (1)
  • Speaking (50)
  • X
  • RSS
Edwin Kwan